Cybersecurity Engineer

Hrtx

Philippines

Hybrid

PHP 1,000,000 - 1,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work setup

Job summary

Hrtx in the Philippines is seeking a Senior SOC Engineer to lead threat detection, incident response, and continuous monitoring within a Security Operations Center.

You will develop SIEM rules, perform threat hunting and forensics, and collaborate with threat intel and engineering teams to enforce logging standards and regulatory requirements. The role also includes mentoring junior analysts and coordinating across cloud and on-prem environments in a hybrid setup.

Qualifications

  • Experience leading real-time monitoring, triage, and response to security incidents.
  • Ability to develop and tune SIEM detection rules and correlation logic.
  • Experience in threat hunting and forensic investigations using logs and network data.
  • Familiarity with regulatory standards (GLBA, FFIEC, PCI DSS) and compliance logging.

Responsibilities

  • Lead real-time monitoring, triage, and response to incidents across cloud and on-prem.
  • Develop SIEM detection rules, use cases, and correlation logic.
  • Perform threat hunting and forensic investigations.
  • Mentor junior SOC analysts and guide escalated investigations.
  • Collaborate with threat intel, engineering, and compliance teams.

Skills

Real-time monitoring
Incident response
Threat detection
SIEM tuning
Threat hunting
Forensic investigations
Log analysis

Tools

GCIH
GSOC
CISSP
CSA

Job description

Our client is seeking a highly skilled and experienced Senior SOC Engineer to lead threat detection, incident response, and continuous monitoring efforts within our Security Operations Center. This role is critical to maintaining the confidentiality, integrity, and availability of our systems and data, especially in a highly regulated financial environment. The ideal candidate will bring deep technical expertise, a proactive mindset, and a passion for defending against evolving cyber threats.

Key Responsibilities
  • Lead and coordinate real-time monitoring, triage, and response to security incidents across cloud and on-prem environments.
  • Develop and tune SIEM detection rules, use cases, and correlation logic to improve threat visibility.
  • Perform threat hunting and forensic investigations using logs, endpoint telemetry, and network data.
  • Collaborate with threat intelligence teams to integrate IOCs and TTPs into detection workflows.
  • Maintain and enhance SOC playbooks, runbooks, and incident response procedures.
  • Mentor junior SOC analysts and provide technical guidance during escalated incidents.
  • Work with engineering and infrastructure teams to implement security controls and logging standards.
  • Support compliance efforts (e.g., GLBA, FFIEC, PCI DSS) by ensuring logging, monitoring, and incident response capabilities meet regulatory requirements.
  • Participate in red/blue/purple team exercises and post-incident reviews.
Qualifications
  • Lead and coordinate real-time monitoring, triage, and response to security incidents across cloud and on-prem environments.
  • Develop and tune SIEM detection rules, use cases, and correlation logic to improve threat visibility.
  • Perform threat hunting and forensic investigations using logs, endpoint telemetry, and network data.
  • Collaborate with threat intelligence teams to integrate IOCs and TTPs into detection workflows.
  • Maintain and enhance SOC playbooks, runbooks, and incident response procedures.
  • Mentor junior SOC analysts and provide technical guidance during escalated incidents.
  • Work with engineering and infrastructure teams to implement security controls and logging standards.
  • Support compliance efforts (e.g., GLBA, FFIEC, PCI DSS) by ensuring logging, monitoring, and incident response capabilities meet regulatory requirements.
  • Participate in red/blue/purple team exercises and post-incident reviews.
Preferred Certifications
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Operations Certified (GSOC)
  • Certified Information Systems Security Professional (CISSP)
  • Certified SOC Analyst (CSA)

Work setup: Hybrid, 3x a week RTO

****FILIPINO CITIZEN ONLY residing in the Philippines***

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Lead
SOC Lead

OFFSHORE BUSINESS PROCESSING INC. • Quezon City

On-site
PHP 558,000 - 614,000
HMO on Day 1
Travel opportunities
Work-life balance
+2
Security Threat Analyst
Security Threat Analyst

Metrobank • Philippines

Hybrid
PHP 1,800,000 - 2,400,000
Security Engineer
Security Engineer

MEC Networks Corporation • Quezon City

On-site
PHP 600,000 - 1,000,000
IT.Senior SOC Analyst
IT.Senior SOC Analyst

Citco Group of Companies • Makati

On-site
PHP 1,004,400 - 1,674,000
Security Threat Analyst
Security Threat Analyst

Metrobank • Taguig

On-site
PHP 1,100,000 - 2,100,000
Security Operations Center Analyst
Security Operations Center Analyst

LanceSoft, Inc. • Metro Manila

On-site
PHP 500,000 - 900,000
Security Operations Analyst II
Security Operations Analyst II

Vertiv Group Corporation • Mandaluyong

On-site
PHP 600,000 - 900,000
Security Operations Analyst II
Security Operations Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 480,000 - 720,000
Security Threat Analyst SOC Manager
Security Threat Analyst SOC Manager

Metrobank • Metro Manila

On-site
PHP 1,200,000 - 2,400,000
Lead SOC Analyst
Lead SOC Analyst

OFFSHORE BUSINESS PROCESSING INC. • Quezon City

On-site
PHP 1,200,000 - 2,400,000